You are viewing limited content. For full access, please sign in.

Question

Question

LFDS19 error when trying to add user into Laserfiche Directory Server

asked on March 24, 2015

Hi All,

 

I've got an error when trying to add a user to the Laserfiche Directory Server. Its "No user found. (LFDS19) after hitting the search button.

 

I originally thought it was because the user didn't have enough access rights to view AD. But I can search and add the user in the LF admin console no problem using the same service account. (I'm guessing the Directory server takes the AD credentials connection from the user the service is running as?)

 

No event are written to the Event Viewer. I'm a bit stumped on where to start looking. The user I am trying to add is on a different domain. What rights does the service account need in the AD tree assuming that is the issue?

 

Thanks!

0 0

Answer

SELECTED ANSWER
replied on March 24, 2015 Show version history

AD searches are actually performed using your windows credentials, "impersonated" by the service user. AD Synchronization is the only action that might use the service user (if no other user was specified for that identity provider).

For security reasons, some directories provide the same error for "Access denied" and "No results", so when this happens, we must take our best guess.  I would expect you to get an access denied dialog with a credentials prompt if the user you are logged in to LFDS as is not able to access that domain, so I am a bit concerned if you are not getting an Access Denied dialog with an option to enter different credentials.

I cannot reproduce: when I try to search a different domain, I am correctly prompted for credentials.

If you are not getting an access denied prompt, but you know your current windows user does not have access to the domain you are searching, you may wish to open a support case as I cannot reproduce this issue.

I have an idea on how to get the credentials prompt until we can figure out why you are not seeing it, but first a note on how LFDS authenticates users:

LFDS uses the Negotiate protocol. If you are access LFDS from a machine other than the one where LFDS is installed, in order to automatically pass your windows credentials, Kerberos must be configured. This is because of the "two hop" problem, similar Web Access using automatic windows authentication. When Kerberos is not configured, LFDS falls back to a different protocol (NTLM) and prompts you to enter your credentials manually. Some browsers (e.g., Firefox) may not work out of the box with the negotiate protocol, and will prompt for credentials even when Kerberos is configured or accessing locally.

What you can try now: try accessing LFDS from a machine other than the one where it is setup (unless you have configured the SPN for the service user), or try using Firefox.

1 0

Replies

replied on March 24, 2015 Show version history

Is this other domain registered successfully as an Identity Provider in LFDS? If so, can you confirm that you've selected the proper Identity Provider when registering this new directory user?

1 0
replied on March 24, 2015

Will have a look at that tomorrow. Remember seeing LFDS options somewhere but didn't click. Cheers Alexander. Will update this post tomorrow.

0 0
replied on March 26, 2015

Hi All,

 

Managed to get to the bottom of this. It was AD account related. The account being used didn't have enough rights to browse AD. Really strange as it's different to the Laserfiche admin console where the same account is being used....

Logged in with a domain admin account when prompted inside LFDS and it could browse with no issues.

 

Cheers!

0 0
replied on August 15, 2017

We are having the same issue on two different installations.  Both have just started having this issue within the last few weeks.   (I wonder if windows updates have changed something).    Both installs are running 10.0.0.222 and one is 10.0.0.270 of Directory server.  Both are running Windows Server 2012 R2.

As with the others, Laserfiche Admin console works fine; but LFDS won't browse AD.

 Are there any particular permissions that the login account needs in regard to AD?

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.